Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
CERT Polska published an attack warning (5 September 2026) describing attackers gaining full administrative control of MikroTik routers whose Secure Shell (SSH) service is reachable from the internet, with no authentication required. Successful attacks date to at least 2 September; no victim count or attacker identity had been published at the time.
| Attribute | Detail |
|---|---|
| Date | From at least 2 September 2026 |
| Vector | Internet-exposed SSH with no authentication |
| Product | MikroTik RouterOS |
| Fix | RouterOS 6.49.21, 7.23.4, 7.24.2 (7.23.5 on the long-term channel to address a regression) |
| Source | CERT Polska โ Tier 1/4 |
MikroTik's security update fixes the issue, and CERT recommends immediate installation followed by a check for unauthorised configuration changes. Home devices with MikroTik's default firewall rules intact are not exposed because public access to management ports is blocked by default. The episode underscores the ongoing risk of internet-exposed management services on edge devices โ a recurring theme across the KEV cadence and NCSC UK's guidance on edge-device hygiene.
Related Pages
- Attackers Conceal Phishing Lures Using Invisible Unicode Characters โ same digest; phishing evasion
- Patch Gap Zero Day Weaponisation โ related exposure-era tradecraft